NSA, FBI Warn Hackers Use AI Scripts to Target Siemens PLCs
The NSA, FBI, and other federal agencies issued an urgent advisory warning that unidentified threat actors are using AI-generated exploit scripts to target Siemens S7 Series programmable logic controllers (PLCs) at critical infrastructure organizations across the United States. The agencies called the campaign an "active threat" and described the use of AI-assisted development as "an evolution in threat actor capabilities" that dramatically reduces the technical expertise required to develop working industrial control system (ICS) exploitation tools. Operators in the energy, water, and agricultural industries were urged to review the advisory with urgency and take immediate response efforts to harden their PLC environments.
Hackers are leveraging internet scanning platforms — the kind of reconnaissance a port scanner can help defenders simulate — to identify Siemens PLCs exposed to the public internet, then deploying AI-generated scripts that masquerade as legitimate operational technology monitoring solutions. These scripts are designed to harvest credentials and establish footholds for further intrusion, exploiting known vulnerabilities in the Siemens S7 Series alongside custom AI-assisted tooling. Security teams concerned about credential exposure can verify whether their access credentials have leaked using a password checker, and should immediately isolate PLCs from the internet, apply all available patches, and deploy monitoring tools capable of detecting anomalous activity on industrial networks.
"This is not a theoretical risk — it is an active threat," the advisory stated, warning that exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime, equipment damage, and cascading impacts across interconnected systems. The agencies also noted that AI is enabling attackers to adapt quickly to defensive measures, producing custom tools on demand tailored to evade detection in operational technology environments.
The advisory does not attribute the activity to a specific actor, but notes the attacks appear intended as "persistent reconnaissance in targeted sectors and facilities to develop capabilities and prepare to cause operational effects against critical infrastructure." In July, federal agencies warned that Iran-affiliated hackers were targeting PLCs from multiple vendors, including Schneider Electric, Rockwell Automation, and Allen-Bradley, alongside Siemens. Wednesday's advisory clarified that the Siemens-specific guidance should be understood as one subset of a broader threat landscape affecting industrial control systems globally.